Terminology Index
2953 terms
Entity and Identity Correlation
Entity and identity correlation links accounts, sessions, people, devices, workloads, addresses, processes, applications, and data objects while preserving ambiguity and mapping evidence.
Entity and Timeline Pivoting
Entity and timeline pivoting follows stable endpoint, identity, session, process, file, message, destination, and service identifiers across sources and time.
Entra ID Assessment
Assessing the security of Microsoft Entra ID (the cloud identity service formerly Azure AD), reviewing privileged roles, conditional access, app registrations, MFA coverage, and risky configurations, since it is the front door to Microsoft cloud resources.
Enumeration-Resistant Authentication Testing
Enumeration-resistant authentication testing compares controlled known and unknown identifiers to find public differences that reveal account, invitation, tenant, or recovery state.
Enumeration-Resistant Responses
Enumeration-resistant responses keep public registration, sign-in, reset, invitation, resend, and recovery behavior from confirming whether an account or identifier exists.
Ephemeral Cloud Evidence
Ephemeral cloud evidence is incident-relevant state tied to a short-lived resource, execution, memory image, container filesystem, temporary credential, connection, or provider-retention window.
Ephemeral Evidence
Evidence in cloud environments that is short-lived and may disappear quickly, such as data on an auto-scaling instance that is terminated, requiring responders to capture it fast before it is gone.
Ephemeral Evidence Capture
Ephemeral evidence capture prepares and performs collection of short-lived workload, process, network, memory, identity, orchestrator, log, artifact, configuration, and downstream activity before it disappears.
Ephemeral Port
A temporary transport-layer source port selected for a connection from the operating system's configured dynamic range.
Ephemeral Ports
The short-lived, high-numbered ports an operating system temporarily assigns to the client side of a network connection, used for the duration of that connection and then released. They help defenders interpret which side initiated traffic.
Eradication
Removing the cause of an incident, such as malware, persistence, or unsafe access.
Eradication Evidence
Eradication evidence supports removal or neutralization of identified malicious artifacts, persistence, unauthorized access, exploited paths, and configurations while recording remaining uncertainty.
Eradication Verification
Confirming that an attacker and all their footholds, malware, accounts, persistence, have actually been removed from the environment before declaring an incident resolved, rather than assuming eradication succeeded.
Erasure Exception Handling
Erasure exception handling distinguishes data that must be deleted from narrowly retained data supported by an applicable legal exception and defined purpose.
Escalation
Handing an alert or incident to a higher tier, specialist, or team when it exceeds an analyst's scope or authority, such as raising a confirmed intrusion to incident response or a senior analyst. It ensures threats reach the right responders.
Escalation Criteria
The defined conditions that determine when an alert or incident should be escalated, such as confirmed compromise, high severity, sensitive assets, or exceeding an analyst's authority, so escalation is consistent rather than guesswork.
Espionage
Attacks motivated by stealing secrets, intellectual property, state, or trade secrets, intelligence, or sensitive data, typically by well-resourced, patient actors like nation-states who prioritize stealth and long-term access over disruption.
Event Counting and Distinct Counting
Event counting measures total occurrences, while distinct counting measures the number of unique values such as users, hosts, or destinations in the same observation window.
Event ID
A provider-defined numeric identifier for an event type whose meaning also depends on source, channel, version, fields, audit policy, and surrounding records.
Event IDs
Numeric codes that identify specific event types in Windows logs (such as 4624 for a logon), letting defenders search for, filter, and build detections around particular activities recorded by the operating system.
Event Source Security
Securing the event sources and triggers that invoke serverless functions, queues, storage events, API calls, so that functions cannot be invoked maliciously or with attacker-controlled, untrusted input.
Event Time Integrity
Preservation and validation of event-occurrence time, observation time, time-zone meaning, and relevant clock or delivery limitations.
Event-Triggered Review
Reviewing and updating a policy in response to a triggering event, a breach, regulatory change, audit finding, or major business shift, rather than waiting for the scheduled review cycle, so policies stay current with reality.
Events
Individual records of something that happened on a system or network, a logon, a connection, a file change, that are logged and analyzed. Events are the raw units of telemetry that detection and investigation are built on.
Evidence Access Control
Evidence access control limits who can view, change, export, approve, or distribute compliance artifacts according to role, sensitivity, purpose, and engagement scope.
Evidence Automation Limits
Evidence automation limits are the boundaries between what a system can collect or test automatically and what still requires contextual or human judgment.
Evidence Collection
Gathering and preserving the data that supports an investigation, logs, artifacts, screenshots, and records, in a sound, documented way so it accurately reflects what happened and can support decisions or later review.
Evidence Collection (Triage)
Purposeful gathering of the minimum reliable alert, event, entity, sensor-health, asset, identity, and contextual evidence needed for an initial disposition or escalation.
Evidence Integrity
Evidence integrity is confidence that an artifact is complete and has not been altered or substituted without authorization or detection.
Evidence Management
The GRC practice of organizing, storing, and maintaining compliance evidence, control proof, logs, records, so it is current, traceable, and readily available for audits, rather than scrambled together at the last minute.
Evidence Minimization
Evidence minimization captures only the requests, responses, configuration, logs, or synthetic records needed to support a reproducible security conclusion and credible impact.
Evidence Population and Sampling
Evidence population and sampling define and reconcile the complete set of in-scope control occurrences, then select items through a documented method appropriate to the objective, frequency, risk, and reliance.